Problem Statement
Which is a direct example of an SSDF-aligned control?
Explanation
SSDF emphasizes protecting tools and artifacts and proving that secure practices happened. Hardened CI, short-lived credentials, and evidence like signed attestations all support the framework’s outcomes. (Sources: NIST SP 800-218 summary pages.)
Code Solution
SolutionRead Only
CI: ephemeral runner; O I D C to cloud; write-only to release repo; artifact signing enabled
